Vulnerability in Oracle HRMS Product of Oracle E-Business Suite
CVE-2026-62560

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62560?

A security flaw exists within the Oracle HRMS (Norway) component of the Oracle E-Business Suite, affecting supported versions from 12.2.3 to 12.2.15. This vulnerability is easily exploitable by attackers with low privileges when accessing the network via HTTP, leading to unauthorized access to critical data. While primarily impacting the Oracle HRMS (Norway) product, successful exploitation may have broader implications, allowing attackers to gain complete access to various data within the system.

Affected Version(s)

Oracle HRMS (Norway) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.